Junglewise Threat Intelligence

CVE-2022-0766: PYSEC-2026-304 - Server-Side Request Forgery in calibreweb

CVE-2022-0766 · Severity: low · CVSS 3.1 · Published 2026-06-29

Technologies: calibreweb (PyPI). Vendors: PyPI.

Executive brief

calibreweb is a web-based e-book management system that allows users to upload book covers from URLs. A server-side request forgery (SSRF) vulnerability in the cover upload feature allows attackers to make the server connect to internal services by bypassing address blacklist checks, potentially exposing sensitive internal systems or data.

Technical details

calibreweb prior to version 0.6.17 contains an incomplete fix for a prior SSRF vulnerability (CVE-2022-0339). The blacklist used to block requests to localhost and internal addresses fails to block the IP address 0.0.0.0, which resolves to localhost on many systems. An attacker can supply a malicious URL containing 0.0.0.0 in the cover upload functionality to bypass the blacklist and access internal services. This is a network-reachable vulnerability requiring no authentication or user interaction beyond requesting a cover upload. An attacker can use this to perform SSRF attacks against internal services, metadata servers, or cloud metadata endpoints.

Affected products

  • calibreweb calibreweb before 0.6.17

Timeline

  • 2022-03-08: disclosed
  • 2022-03-08: patched: Fixed in version 0.6.17

References

Related threats